5
CVE-2013-1336
- EPSS 19.26%
- Veröffentlicht 15.05.2013 03:36:34
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Erkennungen
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check signatures, which allows remote attackers to make undetected changes to signed XML documents via unspecified vectors that preserve signature validity, aka "XML Digital Signature Spoofing Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ .Net Framework Version 2.0 Update sp2
Microsoft ≫ .Net Framework Version 3.5
Microsoft ≫ .Net Framework Version 3.5.1
Microsoft ≫ .Net Framework Version 4.0
Microsoft ≫ .Net Framework Version 4.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 19.26% | 0.97 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://www.us-cert.gov/ncas/alerts/TA13-134A
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-040
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16559